๐Ÿ” CVE Alert

CVE-2026-78187

LOW 3.1

Piwigo Public Authentication cross site scripting

CVSS Score
3.1
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability has been found in Piwigo 16.3.0. This impacts an unknown function of the component Public Authentication Page. Such manipulation of the argument lang leads to cross site scripting. The attack may be performed from remote. A high complexity level is associated with this attack. The exploitability is said to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 16.4.0 will fix this issue. The name of the patch is 5277a7dee4b8f1a174f1d69e1e2a4e1c82a3fc9e. It is recommended to upgrade the affected component.

CWE CWE-79 CWE-94
Vendor n/a
Product piwigo
Published Aug 24, 2026
Stay Ahead of the Next One

Get instant alerts for n/a piwigo

Be the first to know when new low vulnerabilities affecting n/a piwigo are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

n/a / Piwigo
16.3.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/394569 vuldb.com: https://vuldb.com/vuln/394569/cti vuldb.com: https://vuldb.com/cve/CVE-2026-78187 vuldb.com: https://vuldb.com/submit/885228 github.com: https://github.com/Piwigo/Piwigo/security/advisories/GHSA-rr39-mf4j-6594 github.com: https://github.com/Leousum/VulnPoC/blob/main/Piwigo%2016.3.0/reflected_XSS.md github.com: https://github.com/Piwigo/Piwigo/commit/5277a7dee4b8f1a174f1d69e1e2a4e1c82a3fc9e github.com: https://github.com/Piwigo/Piwigo/releases/tag/16.4.0 github.com: https://github.com/Piwigo/Piwigo/

Credits

๐Ÿ” Leousum (VulDB User)